DEV Community

Cover image for Ethical Hacking Is Only One Layer of Modern Cybersecurity
Tekk NG
Tekk NG

Posted on

Ethical Hacking Is Only One Layer of Modern Cybersecurity

If you're learning cybersecurity, there's a good chance you've encountered the usual roadmap:

Networking → Linux → Python → Kali Linux → OWASP → Penetration Testing

That's a useful starting point.

But there's another part of cybersecurity that doesn't always get enough attention:

What happens after you find the vulnerability?

That's where things get interesting.

Recent cybersecurity discussions in Nigeria increasingly connect technical security with data protection, cloud security, governance and cyber resilience. A Nigeria Computer Society workshop, for example, covered access control, breach prevention, third-party and cloud security risks, privacy-by-design and digital governance alongside cybersecurity.

Nigeria's broader cloud policy direction is also bringing digital sovereignty and infrastructure governance into focus.

The penetration test isn't the finish line

Suppose you're testing an application and discover an insecure API endpoint.

You report it.

Great.

But now the organisation needs to understand:

What can an attacker access?
Is authentication being bypassed?
Does the endpoint expose personal data?
Is the vulnerability present in production?
Are logs capturing exploitation attempts?
What is the remediation priority?
Could the same issue exist elsewhere?

Suddenly, a technical finding has become a risk-management problem.

That's cybersecurity.

Cloud makes this even more interesting

Modern applications are rarely sitting on one physical server.

For example:

Who can access the database?
Are cloud credentials protected?
Are permissions excessive?
Is sensitive data encrypted?
Are logs being monitored?
Can compromised credentials be revoked quickly?
What happens if the cloud environment is unavailable?

This is why cloud security and ethical hacking increasingly overlap.

Then comes data sovereignty

Another question is:

Where is the data actually being stored and processed?

Nigeria's National Digital Cloud Policy places digital sovereignty and safeguards for government and regulated data within its cloud infrastructure framework.

For developers and security engineers, this means infrastructure decisions can have implications beyond performance and cost.

They can also affect:

Security + privacy + compliance + governance.

What should aspiring ethical hackers learn?

Don't abandon the technical fundamentals.

Learn them properly.

But consider expanding your roadmap:

  1. Networking

TCP/IP, DNS, HTTP, ports, routing and network security.

  1. Linux

Command line skills, permissions, processes and system administration.

  1. Web security

OWASP Top 10, authentication, authorisation, APIs and common web vulnerabilities.

  1. Penetration testing

Learn how to identify, validate and responsibly report vulnerabilities.

  1. Cloud security

Understand IAM, permissions, secrets, logging and common cloud misconfigurations.

  1. Security operations

Learn how organisations detect, investigate and respond to threats.

  1. Governance and compliance

Understand why security controls exist and how organisations demonstrate that those controls are working.

This is the direction cybersecurity is moving toward: technical depth combined with a better understanding of the environment around the technology.

For learners in Nigeria, TEKHUB [www.tekhub.ng] includes Ethical Hacking + Cyber-Security in its academy, with practical areas such as Kali Linux, OWASP, penetration testing, vulnerability assessment and network security.

The goal of ethical hacking isn't to become better at breaking things.

It's to become better at understanding how things can break—and helping organisations prevent it.

Top comments (0)